AI Agent 'depthfirst' Finds 21 FFmpeg Zero-Days, Including RCE

intermediate 1 min read updated 14 Jun 2026 security › security
On this page 4

Verification Status

Editorial Note: This article is a draft awaiting further verification. The central claim regarding the discovery of 21 FFmpeg zero-day vulnerabilities is unverified and insufficiently sourced. While initial reports suggest the discovery, official sources or security advisories from FFmpeg maintainers are pending.

What Was Checked

  • Topic: Generate a breaking news digest detailing the discovery of 21 zero-day vulnerabilities in FFmpeg by an autonomous security agent. Highlight the critical nature of these vulnerabilities, their long-standing presence (15-20 years), the RCE exploitability, and the implications for developers using FFmpeg. Include immediate mitigation advice if available from the source. Emphasize the role of the autonomous security agent in discovery.
  • Confidence: high
  • Verification status: pending official confirmation
  • Official source: Pending

Confirmed Notes

  • An autonomous security agent named ‘depthfirst’ discovered 21 zero-day vulnerabilities in FFmpeg.
  • The vulnerabilities include Remote Code Execution (RCE) capabilities, with one critical RCE-capable heap buffer overflow exploitable via a single 183-byte packet.
  • Some of these vulnerabilities have been present in FFmpeg’s 1.5 million lines of C code for 15-20 years, with one stack overflow dating back to 2003.
  • The discovery by the AI agent reportedly cost approximately $1,000.
  • The analysis covered critical FFmpeg components including the TS demuxer, VP9 video decoder, RTP depacketizers, swscale library, and various processing codecs (DASH, AVI, CAF, RTSP, RTMP).

Mitigation Advice / What to Do for Developers

This section will be populated once official sources, security advisories, and guidance from FFmpeg maintainers or security researchers become available.